7.8

CVE-2022-38076

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.

Data is provided by the National Vulnerability Database (NVD)
IntelKiller Version < 34.22.1163
   IntelDual Band Wireless-ac 3165 Version-
   IntelDual Band Wireless-ac 3168 Version-
   IntelDual Band Wireless-ac 8260 Version-
   IntelDual Band Wireless-ac 8265 Version-
   IntelKiller Wireless-ac 1550 Version-
   IntelWireless-ac 9260 Version-
   IntelWireless-ac 9461 Version-
   IntelWireless-ac 9462 Version-
   IntelWireless-ac 9560 Version-
   IntelWireless 7265 (rev D) Version-
IntelProset/wireless Wifi Version < 22.200
   IntelDual Band Wireless-ac 3165 Version-
   IntelDual Band Wireless-ac 3168 Version-
   IntelDual Band Wireless-ac 8260 Version-
   IntelDual Band Wireless-ac 8265 Version-
   IntelKiller Wireless-ac 1550 Version-
   IntelWireless-ac 9260 Version-
   IntelWireless-ac 9461 Version-
   IntelWireless-ac 9462 Version-
   IntelWireless-ac 9560 Version-
   IntelWireless 7265 (rev D) Version-
IntelUefi Firmware Version < 3.2.20.23023
   IntelDual Band Wireless-ac 3165 Version-
   IntelDual Band Wireless-ac 3168 Version-
   IntelDual Band Wireless-ac 8260 Version-
   IntelDual Band Wireless-ac 8265 Version-
   IntelKiller Wireless-ac 1550 Version-
   IntelWireless-ac 9260 Version-
   IntelWireless-ac 9461 Version-
   IntelWireless-ac 9462 Version-
   IntelWireless-ac 9560 Version-
   IntelWireless 7265 (rev D) Version-
FedoraprojectFedora Version37
FedoraprojectFedora Version38
FedoraprojectFedora Version39
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.261
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secure@intel.com 3.8 2 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.